8.5

CVE-2010-2892

Exploit
gsb/drivers.php in LANDesk Management Gateway 4.0 through 4.0-1.48 and 4.2 through 4.2-1.8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the DRIVES parameter, as demonstrated by a cross-site request forgery (CSRF) attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LandeskManagement Gateway Version4.0
LandeskManagement Gateway Version4.0-1.48
LandeskManagement Gateway Version4.2
LandeskManagement Gateway Version4.2-1.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.51% 0.877
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.5 6.8 10
AV:N/AC:M/Au:S/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://community.landesk.com/support/docs/DOC-21767
Vendor Advisory
http://secunia.com/advisories/42188
Vendor Advisory
http://securitytracker.com/id?1024728
http://www.coresecurity.com/content/landesk-os-command-injection-vulnerability
Exploit
http://www.exploit-db.com/exploits/15488
Exploit
http://www.securityfocus.com/archive/1/514728/100/0/threaded
http://www.securityfocus.com/bid/44781
Exploit
http://www.vupen.com/english/advisories/2010/2957
Vendor Advisory